Features
To Prevent Supply Chain Attacks, Build Secure Code
More than a year after the massive SolarWinds cyberattack, targeted companies continue to feel its ramifications in both reputation and financial cost. Moreover, the global software supply chain remains vulnerable to severe ...
Survey Warns of Looming Software Testing Crisis
A survey of CEOs and IT professionals involved in application testing finds a significant gap in terms of how acceptable it is to release software that has not been properly tested. The ...
Deloitte Aligns with Dynatrace for Observability
Deloitte has expanded its cloud observability practice to include the Dynatrace Software Intelligence platform. Jay McDonald, managing director and co-chair for modern delivery at Deloitte, said the IT services provider will now ...
JFrog Integrates DevOps Portfolio With Microsoft Teams
JFrog this week announced it has integrated its DevOps portfolio with Microsoft Teams to enhance collaboration. Deep Datta, a senior product marketing manager for JFrog, said JFrog Artifactory repository and the JFrog ...
Red Hat CEO: Out | Blind Users: Revolt | ARM: Google Joins Party
In this week’s The Long View: Matt Hicks is the new Red Hat CEO, visual accessibility is in focus, and Google Cloud rolls out ARM instances ...
Security Compass Makes Visualizing AppSec Threats Simpler
Security Compass this week updated its threat modeling platform for developers to make it easier to surface application security issues. The latest version of SD Elements 2022 adds support for developer-centric threat ...
Scribe Security Unveils Pair of Tools to Secure Software Supply Chains
Scribe Security today unveiled a Scribe Integrity tool that scans software artifacts to make sure they comply with IT organizations' security policies before they are integrated into an application. The Scribe Integrity ...
Styra Unfurls Cloud Service for Implementing Compliance-as-Code
Styra, Inc. today launched an authorization service based on the Open Policy Agent (OPA) software that can be invoked via an application programming interface (API). Torin Sandall, vice president of open source ...
CodeLogic Toolkit Increases Visibility Into App Dependencies
CodeLogic launched today a toolkit that enables developers to scan binaries, runtime application behavior and database connections and then leverage graph technology to identify connections and dependencies in real-time. Brian Pierce, CodeLogic ...
Rezilion Launches Vulnerability Prioritization Platform
Rezilion today announced general availability of a platform that enables DevOps teams to better prioritize remediation efforts by identifying which vulnerabilities both run in memory and actually impact a class or function ...
GitGuardian Tightens Integration With GitHub to Secure Secrets
GitGuardian has expanded its ability to secure code repositories by providing deeper integration with GitHub. Ziad Ghalleb, product marketing manager for GitGuardian, said the results of security scans are now provided in ...
The Quest To Unify With GraphQL, The Modern Data API
There is an ongoing trend in enterprise software: Using GraphQL as an aggregation layer to unify access to underlying data sources and REST APIs. Some call this the supergraph, and others refer ...

